aboutsummaryrefslogtreecommitdiff
path: root/nix/users/fcuny/ssh.nix
blob: 322a8bc30b92a4d977921d4e6ff590e671bb60d7 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
{ pkgs, config, ... }:
{
  # https://github.com/nix-community/home-manager/blob/master/modules/programs/ssh.nix
  programs.ssh = {
    enable = true;
    forwardAgent = true;
    serverAliveInterval = 60;
    controlMaster = "auto";
    controlPersist = "30m";
    controlPath = "${config.home.homeDirectory}/.ssh/sockets/S.%r@%h:%p";

    matchBlocks = {
      "git.fcuny.net" = {
        proxyCommand = "${pkgs.cloudflared}/bin/cloudflared access ssh --hostname %h";
      };
      "github.com" = {
        hostname = "github.com";
        user = "git";
        forwardAgent = false;
        extraOptions = {
          preferredAuthentications = "publickey";
          controlMaster = "no";
          controlPath = "none";
        };
      };
      "github.rbx.com" = {
        hostname = "github.rbx.com";
        user = "git";
        forwardAgent = false;
        extraOptions = {
          preferredAuthentications = "publickey";
          controlMaster = "no";
          controlPath = "none";
        };
      };
    };
  };

  home.file = {
    # we need this path to be created so that the control path can be used.
    ".ssh/sockets/.keep".text = "# Managed by Home Manager";
  };
}